PT-2025-25174 · K7 · K7 Security Anti-Malware Suite

·

CVE-2025-1055

·

Published

2025-06-10

·

Updated

2026-06-25

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions K7 Security Anti-Malware (affected versions not specified)
Description A flaw in the K7RKScan.sys driver allows a local low-privilege user to send crafted IOCTL (Input/Output Control) requests to terminate various processes running with administrative or system-level privileges, excluding those inherently protected by the operating system. This issue is caused by missing access control in the driver's IOCTL handler, which enables unprivileged users to perform privileged actions within the kernel space. Successful exploitation can result in a denial of service by disrupting privileged applications or critical services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1055

Affected Products

K7 Security Anti-Malware Suite